You can use the Rate Limiting feature to control the rate of egress traffic sent through the ports of a Sensor. When deployed in inline mode, Sensor permits rate limiting of traffic by limiting the bandwidth of the traffic that goes through the Sensor ports. Traffic that is less than or equal to the specified bandwidth value is allowed, whereas traffic that exceeds the bandwidth value is dropped. The Sensor uses the token bucket approach for rate limiting traffic. An administrator can set appropriate values in the Manager to prevent DoS by setting Sensor port specific bandwidth limits that are relevant for preventing DoS in a particular network. The Rate Limiting feature is available as part of the Quality of Service (QoS) policies.
You can rate-limit by protocol such as P2P, HTTP and ICMP as by TCP ports, UDP ports, IP protocol number, and various other parameters including applications, Windows Active Directory user name, geographical location. For more details see the Quality of Service chapter.
Trellix IPS provides rate limiting configuration at individual Sensor ports. For example, if 1A-1B is a port-pair, QoS policy is configured separately for 1A and 1B. QoS policy for a port applies to egress traffic only.
Rate limiting is very effective when applied in a specific context with full knowledge of the nature of traffic in a particular network. Rate limiting needs to be applied carefully as it might drop legitimate traffic as well.
Note
Rate limiting is not supported on NS9500, NS9300, NS9200, NS9100, NS7500, NS7350, NS7250, NS7150, NS7300, NS7200, NS7100, NS5200, NS5100, NS3500, NS3200, NS3100, and IPS-VM600 Sensors.